If your company is not Spanish, an ENS clause in a Spanish public tender is easy to miss and easy to underestimate. It is not a generic "please be secure" line: the ENS is a mandatory security framework with defined categories, defined roles and a formal conformity process. The good news is that the first two weeks are not about "getting certified" — they are about understanding exactly what is being asked and making three or four decisions that stop you working in the wrong direction. Here is the order.
What the ENS actually is
The ENS (Esquema Nacional de Seguridad, Spain's National Security Framework) is the security standard that applies to Spanish public-sector information systems and, by extension, to the private suppliers that operate or handle information for them. It is governed by Royal Decree 311/2022. When a tender says a bidder must be "compliant with the ENS", it is pointing at this framework — not at ISO 27001, and not at a general best-practice statement. If you sell to the Spanish public sector, it is increasingly a condition you cannot skip.
First decision: which ENS category the tender requires
The system category — basic, medium or high — is the first thing to extract from the tender, because it sets the level of rigour, the number of applicable measures and, above all, whether you need a declaration or a certification.
Royal Decree 311/2022 classifies systems by the impact an incident would have across five security dimensions: availability, authenticity, integrity, confidentiality and traceability (Annex I). The highest level reached in any single dimension fixes the category of the whole system. Many tenders state the category outright ("ENS certification at MEDIUM category is required"); others leave it implicit. If the tender does not specify it, that is the first written question to the contracting authority — not a guess.
Second decision: conformity declaration or certification?
The category determines the conformity mechanism. Under article 38 of Royal Decree 311/2022, basic-category systems can demonstrate conformity through a self-assessment that results in a conformity declaration. Medium and high-category systems require a certification audit carried out by a certification body accredited by ENAC, Spain's national accreditation body. The certificate is valid for two years, with ordinary audits at least every two years.
These are not the same exercise or the same timeline. Be honest about the calendar: a tender deadline does not compress an accredited audit. What you can prepare inside that window is everything that makes the audit, when it comes, uneventful. If the tender uses the generic phrase "ENS conformity" without naming which, it is worth separating declaration from certification before scoping any work.
The article 11 problem: who can be the security officer
The obvious person to "own the ENS" is the head of IT or systems. That is exactly the person Royal Decree 311/2022 rules out. Article 11 requires four responsibilities to be differentiated — information, service, security and system — and its second paragraph states that responsibility for the security of information systems shall be differentiated from responsibility for their operation.
In practice: the person who operates the systems cannot also be the person who decides and oversees security. The regulation allows exceptions, but they must be documented and paired with compensating measures; they are the justified exception, not the rule. Filling the role with an internal hire is not a minor line either — a CISO in Spain sits at around €100,000–120,000 gross per year according to Setesca Talent's 2026 IT salary report, rising to €180,000 for senior profiles (Robert Walters). For a non-Spanish supplier, standing up a segregated Spanish security function for a single tender is even harder to justify.
Week 1: categorise, read the tender, assign responsibilities
The aim of week one is to turn a clause in the tender into a clear scope and assigned roles.
- Extract the required category and mechanism (declaration or certification) from the tender. If it is not explicit, ask the contracting authority in writing.
- Define the scope: the specific information system that supports the tendered service, not the whole company.
- Assign the four article 11 roles, keeping security separate from operations. If you use an exception, document why and with what compensating measures.
- Identify the applicable CCN-STIC guides for your category: they are the criteria you will be audited against.
- Inventory what you already have against what the ENS requires. If you already run ISO 27001, much of the documentation base can be reused — running ISO 27001 and the ENS as one programme avoids duplicating the work.
Week 2: gap analysis, adequacy plan and choice of path
The aim of week two is to know how far you are from the ENS and decide how you cover it before committing in the bid.
- Complete the gap analysis against the Annex II measures for your category.
- Draft the adequacy plan with owners and realistic dates: it proves you know what is missing and how you will close it.
- Start the statement of applicability: which measures apply, which do not, and why.
- Choose the path: self-assessment (basic) or contacting an accredited body to schedule the audit (medium or high). Ask for real audit dates.
- Move those dates into the bid: what you can evidence on submission day, and what will sit in the adequacy plan.
The timeline mistake that can cost you the contract
The most expensive mistake is promising, in the bid, a certificate you cannot hold on submission day. If the tender allows conformity to be demonstrated during execution — and many do — the defensible move is to present the adequacy plan and the audit schedule, not to claim a certification that does not yet exist. If it demands certification as a prior eligibility requirement, the week-two timeline analysis tells you whether you make it. Committing to a certification date that depends on an external accredited body, without having spoken to one, is the fastest way to lose an award at the execution stage.
How to take on the ENS without building a Spanish security team
The underlying tension: the ENS obliges you to have a real security function, separate from IT (article 11), but standing one up internally costs six figures a year and cannot be improvised inside a tender window — more so from outside Spain. The alternative is to operate that function externally and continuously. Qalea acts as the security team most companies of this size cannot keep in-house: it takes on the security role, segregated from your systems operation, builds the ENS documentation and control base, and leaves you ready to face the audit. It does not replace the certification body — which is what issues the certificate — nor promise timelines that depend on it.
Send us what your tender demands and we will tell you which category you are in and whether you can make it.








